Selective Digital Identity Attribute Sharing via Encrypted Codes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies for sharing digital identity documents lack the ability to securely share specific attributes of these documents, leading to potential misuse and unauthorized access, as they often require the entire document to be shared, which is not necessary and increases the risk of fraud.
Innovation Solution
A system and method for securely sharing one or more attributes of a digital identity document by generating a machine-readable encrypted code upon approval from the document owner, allowing controlled access to the requested attributes for a defined period, with masking of other attributes to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If the entire digital identity document is shared with the requesting party, then the requesting party can obtain all necessary information for verification, but the risk of fraud and unauthorized access increases
Solution Approach 1:
The patent segments the digital identity document into individual attributes (name, address, date of birth, etc.) and enables selective sharing of only the specific attributes required by the requesting party, rather than sharing the entire document. This segmentation reduces the information exposure and associated fraud risk while still providing complete verification data for the specific purpose.
Solution Approach 2:
The patent extracts and shares only the specific attributes needed for verification (such as name and address for an ISP) from the complete digital identity document, leaving the remaining attributes private. This extraction principle allows the requesting party to obtain sufficient information for their purpose without accessing unnecessary or sensitive data that could increase fraud risk.
2Ease of operation
If digital copies of identity documents are stored in service provider databases, then verification convenience is improved, but the security risk of data compromise and unauthorized access increases
Solution Approach 1:
The patent extracts only the specific attributes needed for verification from the digital identity document and shares them with the service provider, rather than storing complete digital copies in their databases. This extraction approach maintains verification convenience while significantly reducing the security risk associated with storing comprehensive personal data.
Solution Approach 2:
The patent implements local quality by providing different levels of information access to different service providers based on their specific verification needs. Each service provider receives only the attributes relevant to their function (e.g., an ISP receives address and name, while airport security receives photo and name), thereby minimizing the security risk exposure for each entity while maintaining operational convenience.
3Reliability
If the consumer carries original identity documents and photocopies everywhere, then identity verification can be performed by service providers, but the inconvenience of carrying multiple documents increases
Solution Approach 1:
The patent uses digital copies of the identity document stored on the consumer's mobile device instead of physical originals and photocopies. The consumer can share these digital copies selectively with service providers through the application, eliminating the need to physically carry multiple documents while maintaining verification reliability through encrypted digital transmission.
4Ease of operation
If the consumer cannot control access to digital identity data by service providers, then data sharing is simplified, but the ability to prevent unauthorized usage decreases
Solution Approach 1:
The patent implements dynamic access control where the consumer can approve or deny attribute sharing requests in real-time through the application. The system transitions from static, unconditional data sharing to dynamic, consumer-controlled access. The consumer receives notifications and can selectively grant permission for specific attributes to specific service providers, providing both simplicity through automation and versatility through user control.
Data Source
AI summary
Embodiments provide a method for facilitating sharing of digital documents between a sharing party and a relying party. The method includes receiving, by a processing system, an access request for accessing at least one attribute of a digital document. The access request is initiated at a relying party interface in a document sharing application. The method further includes sending, by the processing system, the access request to a sharing party interface in the document sharing application for approval of providing access to the at least one attribute of the digital document by the sharing party to the relying party. The method further includes, upon receiving the approval from the sharing party interface, generating a machine-readable encrypted code for the at least one attribute of the digital document. The method further includes sending the machine-readable encrypted code to the relying party interface.


